The quantum attack surface is bigger than it seems
EO 14412 and M-26-15 prioritize high-value system migration, but the trust infrastructure that keeps federal networks authenticating, routing, and verifying software updates sits outside the mandate, and adversaries won't wait for separate guidance.
TL;DR
The White House and OMB have set hard deadlines for migrating high-value and high-impact federal systems to post-quantum cryptography, key establishment by 2030, digital signatures by 2031. But the mandates are silent on the broader trust infrastructure those systems depend on: PKI, device identity, code-signing, network routing, and forensic logs. A cryptographically relevant quantum computer wouldn't need to crack the prioritized systems directly. It could forge certificates, redirect traffic, or push malware through trusted update channels, and the agencies that followed the mandate to the letter would still be exposed. With Google, Microsoft, and Cloudflare targeting 2029 for their own PQC migrations, the gap between what's mandated and what's actually protected is a vulnerability window measured in years.
The White House has made protection against quantum computing threats a national priority. Executive Order 14412 requires agencies to migrate high-value assets and high-impact systems to post-quantum key establishment by the end of 2030, with digital signatures to follow by 2031. The Office of Management and Budget's guidance (M-26-15) lays out a phased plan: inventories and strategy through 2027, pilots and early migrations through 2028, then execution.
But the mandate addresses only part of the problem. Much of the infrastructure that establishes digital trust (routing protocols, device identities, software supply chains, and forensic integrity) falls outside a traditional system-by-system approach. These aren't edge cases. They're the scaffolding that makes prioritized systems work.
The threat is bigger than stored data.
The dominant quantum-computing scenario has been "harvest now, decrypt later", adversaries stealing encrypted data today to crack once a cryptographically relevant quantum computer (CRQC) arrives. That's real. It's also not the whole story.
What a CRQC does to identity
After a CRQC arrives, breaking into a federal network may not require stolen passwords or software vulnerabilities. A quantum computer can derive private keys from public certificates and generate valid credentials for virtually any identity, from a help desk technician to a senior official. Public key infrastructure, Common Access Cards, certificate-based authentication, and the digital signatures underpinning zero trust all rely on cryptography that CRQCs can defeat.
Once that happens, security checkpoints treat the attacker as legitimate. They move through the network undetected because, cryptographically, everything checks out.
Network trust, broken
Each time an agency connects to a cloud provider or mission partner, both sides exchange certificates to verify identity. A quantum-enabled attacker can forge those certificates so the agency believes it's communicating with a trusted endpoint while traffic is quietly redirected. Monitoring tools won't flag it, the cryptography says it's valid.
The same weakness extends to the internet's core infrastructure. Domain Name System Security Extensions and routing protocols rely on digital signatures to ensure traffic reaches the right destination. Forged signatures can redirect agency communications before traditional defenses register anything unusual.
When updates become attack vectors
Software updates and firmware patches installed across the federal government are authenticated by code-signing certificates that prove they came from a trusted source. If attackers can forge that certificate, they can distribute malware through trusted update channels, and it'll pass every cryptographic validation check.
The supply chain is the gap
Contractors, integrators, and cloud platforms are embedded in federal IT. Every connection relies on the same cryptography that quantum computing threatens. One unmigrated vendor becomes an entry point into an otherwise hardened environment. Attackers don't need to compromise the agency itself. They only need the weakest link.
Erasing the evidence
Agencies rely on audit logs to understand what happened during a breach, who accessed what, when. Those records are trusted because digital signatures protect them. If quantum computing breaks those signatures, attackers can alter or erase evidence of their own activity, making it far harder to investigate incidents or even determine whether the logs themselves remain trustworthy.
What to do now
The practical steps are clearer than the policy gap. Agencies need to identify not just the systems that store sensitive data but the long-lived certificates and keys that will still be protecting those systems when CRQCs arrive, root certificates, code-signing keys, and embedded device credentials.
They need to look beyond the systems they directly own. Internet routing, DNS infrastructure, operational technology, supply chains, and vendor connections won't appear on traditional asset inventories but remain part of the quantum attack surface.
And they need to design for crypto-agility. Change is a certainty. Algorithms will be broken, standards will evolve, and today's PQC transition won't be the last. Cryptography should be replaceable without redesigning entire systems, turning future migrations into routine upgrades rather than multi-year modernization efforts.
The mandate doesn't yet cover these gaps. The adversaries won't wait for it to catch up.
Published ·Deep Fathom